Insurance firm Alan Boswell Group examined password data from Have I Been Pwned, a public repository containing credentials exposed across thousands of data breaches, to map the words, names, years, and pop-culture references people keep choosing. The findings are less a surprise than a confirmation: the same weak choices persist across personal and professional accounts alike.
'123456' tops the list at 209,972,844 occurrences. '123456789' and '12345678' follow. 'Password' itself appears more than 52 million times; 'admin' — the default credential on misconfigured enterprise systems — more than 42 million. The top ten is completed by 'qwerty', '1234', '1234567', and '1234567890'.
Name-based passwords are similarly persistent. 'Daniel' leads with 2.5 million exact matches, followed by 'Michael' and 'Jessica'. Among years, 2020 tops the count at nearly 1.5 million, possibly reflecting account creation spikes during the pandemic. The presence of years like 1989, 1990, and 1994 in the top ten points to people using their birth year — easily guessable from a LinkedIn profile.
Sports teams and pop culture round out the data. Liverpool is the most commonly used football club password at 1.79 million occurrences, followed by Barcelona and Juventus. 'Blink-182' leads the music category at 1.65 million, ahead of Metallica and Eminem. 'Superman' is the most common fictional character at 2.1 million, ahead of Naruto and Batman.
The business angle is more pointed than the headline figures suggest. These are not passwords being guessed — they are passwords already sitting in automated credential-stuffing lists, ready for replay attacks against corporate VPNs, email systems, and customer portals. 'Admin' in the top five is a particular red flag: it suggests a significant portion of breached credentials come from systems that were never properly configured after deployment.
Heath Alexander-Bew, personal lines director at Alan Boswell Group, tied the figures to regulatory and financial exposure: the UK Government's 2026 Cyber Security Breaches Survey found 43% of UK businesses experienced a breach or attack in the past year. The most serious cases carry minimum costs of £4,000 per incident for smaller organisations, rising to £10,000 for medium and large ones.
The firm recommends that businesses block leaked passwords at the system level rather than relying on user behaviour, enforce multi-factor authentication, and encourage use of password managers. Individuals with affected accounts should also audit recovery details and email forwarding rules — because an attacker who has already been inside an inbox may have set up silent exfiltration before the password was changed.
To stay across the latest in cloud, AI and enterprise tech analysis from Compare the Cloud, subscribe to our weekly newsletter at https://www.comparethecloud.net/newsletter